dbs-chatroom
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill structure allows user-supplied text to influence the instructions given to expert sub-agents, creating a surface for potential injection attacks.
- Ingestion points: User-provided topics and questions are ingested into placeholders such as
{用户的话题}and{用户本轮的问题}withinSKILL.md. - Boundary markers: The skill does not employ explicit delimiters or 'ignore instructions' warnings to isolate these user-controlled strings within the expert agent prompts.
- Capability inventory: The skill demonstrates the capability to spawn and command multiple expert agents via the
Agent toolas described inSKILL.md. - Sanitization: No sanitization, validation, or escaping mechanisms are applied to the user input before it is passed to the sub-agents.
Audit Metadata